CVE-2025-6624
- EPSS 0.02%
- Published 26.06.2025 05:15:23
- Last modified 09.07.2025 17:53:54
Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be expo...
CVE-2024-48963
- EPSS 0.05%
- Published 23.10.2024 19:15:19
- Last modified 30.10.2024 14:54:53
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working direc...
CVE-2024-48964
- EPSS 0.05%
- Published 23.10.2024 19:15:19
- Last modified 30.10.2024 13:46:31
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working di...
CVE-2022-22984
- EPSS 1.2%
- Published 30.11.2022 13:15:10
- Last modified 25.04.2025 15:15:30
The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin...
CVE-2022-24441
- EPSS 1.46%
- Published 30.11.2022 13:15:10
- Last modified 24.04.2025 20:15:22
The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be...